{"data":{"id":"d7f6b688-fcc1-4b5a-aa5b-ffd8fe3eee9e","title":"CVE-2026-94622: vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for pre","summary":"vLLM (a system for running large language models) versions up to 0.29.0 have a denial of service vulnerability (a flaw that lets attackers crash a service) in how the NIXL connector handles metadata for split deployments. An attacker can send specially crafted requests that cause an uncaught KeyError (a programming error where the code tries to access a dictionary key that doesn't exist) in the scheduling system, crashing the decode engine and forcing a manual restart to recover.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94622","publishedAt":"2026-09-21T22:17:00.960Z","cveId":"CVE-2026-94622","cweIds":["CWE-248"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-21T22:17:00.960Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}